New AI Tool FraudGPT Poses Serious Threat to Individuals and Businesses

FraudGPT [1] [2] [3] [4] [5] [6], an offensive AI bot, has emerged on the Dark Web and Telegram platform [6], posing a serious threat to individuals and businesses [6]. This all-in-one tool for cybercriminals offers features such as social engineering and Business Email Compromise (BEC) attacks.


FraudGPT is a tool that enables threat actors to create convincing emails, enticing recipients to click on malicious links [4]. It is particularly useful for BEC phishing campaigns, as it aids attackers in identifying targeted services and defrauding victims. The tool has gained popularity, with over 3,000 confirmed sales and reviews on various Dark Web marketplaces. Subscription fees for FraudGPT range from $200 per month to $1,700 per year [2] [4]. Interestingly, the individual behind FraudGPT was previously active on Dark Web marketplaces but has now shifted to Telegram to avoid exit scams [2]. Another AI tool called “WormGPT” was discovered on July 13, offering advanced phishing email generation and BEC attack services [6]. Within a week of its launch [6], WormGPT gained over 5,000 active subscribers on its Telegram channel [6]. The increasing use of AI tools like FraudGPT and WormGPT highlights the growing trend of threat actors leveraging advanced technology for cybercriminal activities. These tools enable convincing phishing and BEC attacks, resulting in the theft of sensitive information and unauthorized wire payments [1]. The person responsible for FraudGPT maintains a Telegram Channel and claims to be a verified vendor on multiple Dark Web marketplaces [4]. They advertise hacking activities and can be contacted via the email address


The emergence of offensive AI bots like FraudGPT and WormGPT poses significant threats to individuals and businesses. These tools enable cybercriminals to conduct convincing phishing and BEC attacks, leading to the theft of sensitive information and unauthorized wire payments [1]. To effectively combat these threats, implementing a defense-in-depth strategy with security telemetry is crucial [1]. It is important to stay vigilant and take proactive measures to protect against these advanced cybercriminal activities.




